Security Advisories
Published OpenWISP security advisories are listed below, newest first. Follow the GitHub advisory links for affected and fixed versions, mitigations, and required operator actions.
2026-09-15, OpenWISP RADIUS (GHSA-pfx3-4m53-g475): SMS verification bypasses destination and IP restrictions.
2026-06-15, OpenWISP IPAM (GHSA-x287-5c68-36wp): Broken object-level authorization allows exporting another organization's subnet and IP addresses.
Announcements are also sent to the OpenWISP mailing list. To report a new suspected vulnerability privately, follow the instructions in Disclosing Vulnerabilities.